Files
buildroot/package/bubblewrap/bubblewrap.hash
Adrian Perez de Castro 110d3ecb81 package/bubblewrap: security bump to version 0.12.0
Fixes a sandbox escape through symlink traversal tracked in
CVE-2026-87766, which affects all previous versions.

Using the bwrap binary with the setuid bit set is no longer supported
and user namespaces are now always required, so a kernel config fixup
is applied.

A new build option allows indicating the minimum kernel version that
will be used, which removes code used for backwards compatibility with
kernels older than 5.6.0 when a newer version is specified. Passing
$(LINUX_VERSION_PROBED) seems reasonable here.

This version also changed the license from LGPL-2.0+ to LGPL-2.1+,
hence the updated hash.

Release notes:

  https://github.com/containers/bubblewrap/releases/tag/v0.12.0

Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
[Julien: fix _LINUX_CONFIG_FIXUPS by adding the missing "_LINUX"]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 4cb6193d2e)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:45:33 +02:00

6 lines
317 B
Plaintext

# From https://github.com/containers/bubblewrap/releases/download/v0.12.0/bubblewrap-0.12.0.tar.xz.sha256sum
sha256 9760d007363e3abba7c747489910f9f82d9fca53ba3bd3282e396fa3c97a3314 bubblewrap-0.12.0.tar.xz
# Hash for license files:
sha256 dc626520dcd53a22f727af3ee42c770e56c97a64fe3adb063799d8ab032fe551 COPYING